Anthem Inc. disclosed a criminal cyber intrusion on February 4, 2015 that ultimately exposed the records of 78.8 million people, making it the largest U.S. health-insurer breach until Change Healthcare in 2024. Investigators traced the initial unauthorized access to February 18, 2014, with state insurance commissioners attributing the campaign to a foreign-government-directed threat actor. Stolen data included names, dates of birth, member identification numbers, Social Security numbers, street and email addresses, and employment information, though Anthem maintained that medical records and financial data were not taken. The estimate was revised from 37.5 million records at first disclosure to 78.8 million by February 24, 2015. Anthem resolved roughly 100 consolidated class actions for $115 million in 2017, the then-largest U.S. data-breach settlement, and paid a $16 million HHS Office for Civil Rights HIPAA settlement in October 2018, eclipsing the prior $5.55 million Advocate Health Care record. A 43-state attorney general coalition settled for an additional $39.5 million in 2020, with related multistate resolutions bringing aggregate payouts to roughly $179 million. The OCR corrective action plan required an enterprise risk analysis, remediation of identified vulnerabilities, and multi-year compliance reporting.
Blog
Insights on AI security and development
Learn how to protect your code, understand AI risks, and build secure workflows with expert insights.

